Open in ClaudeOpen in ChatGPT

Security audit log

The following page explains the different events that are logged when using the ‘Security audit log’.

A ‘Security audit log’ can be used to track relevant activities performed in Valsight.

The relevant files to activate the security audit log are located in the Valsight settings (navigation bar) → Metric and Logs → Download ‘Valsight Security Audit Log Files (ZIP)’.

What is logged?

Each event has the following aspects that are logged via the security audit log:

HeaderDescription
TimeWhen the event occurred
UserThe logged in user who caused the event
Object typeOn what object type has the vent occurred (Group. User, Project, Model, …)
Object keyThe exact object on which the event occurred
ProjectThe exact project in which the event occurred
Action typeWhich event occurred
Action parameter1Additional info if all other headers aren’t enough
Action parameter2Additional info if all other headers aren’t enough
Action parameter3Additional info if all other headers aren’t enough

Precise details about newly logged objects and what we log on them:

Domain ObjectAction TypeDetail
AssumptionGroupProperty changeName
DataParameterDeletedExcept when deleted by deleting a workspace, model or project
DataParameterProperty changeEverything except description
DataParameterVariantLine-item data changeN/A
DataParameterVariantDeleteExcept when deleted by deleting a workspace, project or data parameter
DimensionCreatedN/A
DimensionDeletedExcept when deleted by deleting a project
DimensionProperty changeEverything except description
ExternalDataSourceDeletedExcept when deleted by deleting a project
LevelCreatedN/A
LevelDeletedN/A
LevelProperty changeEverything
ModelProperty changeOnly modelConfig changes are logged
ModelDeletedExcept when deleted by deleting a project
NodeProperty changeEverything except description and displayConfig
PlanningWorkflowDeletedExcept when deleted by deleting a project
ProjectVariableCreatedN/A
ProjectVariableProperty changeBoth name and value
ProjectVariableDeletedExcept when deleted by deleting a project
ScenarioExportTemplateDeletedExcept when deleted by deleting a project
SimulationRunProperty changeThe values name, baseline and parentSimulationRun
SimulationRunDeletedExcept when deleted by deleting a project or workspace
SimulationRunVariableCreatedN/A
SimulationRunVariableProperty changeIncludes the value of the original. This also logged when we create a variable override, to log the changes between the project’s and scenario’s values.
SimulationRunVariableDeletedExcept when deleted by deleting a project, model, workspace or scenario
SimulationWorkspaceProperty changeEverything in the simulationConfig
SimulationWorkspaceDeletedExcept when deleted by deleting a project
WorkflowStepDeletedExcept when deleted by deleting a workflow or project

Logged events

Add+Create/Remove+Delete/Change

EventAction typeAction Parameter 1Action Parameter 2Action Parameter 3Added in Version
Adding permissionsAdded permissionFor which user/group is the permission addedN/AN/ASince beginning
Adding a role to the user or groupAdded rolename of the roleN/AN/ASince beginning
Adding an user to a groupAdded user to groupuserN/AN/ASince beginning
Creating an user or groupCreated’preAuth’, ‘SAML’, ‘openIdConnect’ or no parameterN/AN/ASince beginning
Create project variablesCreated‘value’variable valueN/A5.8.0
Update project variablesProperty changeparameter type either ‘name’ or ‘value’parameter old valueparameter new value5.8.0
Scenario variableCreatedN/AN/AN/A5.8.0
Update scenario variableProperty change‘value’Value of project variable the scenario variable is overridingscenario variable value5.8.0
Delete scenario variableDeletedN/AN/AN/A5.8.0
Dimension row addedProperty changedimRowAddedname of each level and the value added to the level (including extended levels)N/A5.8.0
Removing permissionsRemoved permissionFor which user/group is the permission removedN/AN/ASince beginning
Removing a role from the user or groupRemoved rolename of the roleN/AN/ASince beginning
Removing user from the groupRemoved user from the groupuserN/AN/ASince beginning
Deleting an user or groupDeletedN/AN/AN/ASince beginning
Node deletionDeletednames of the node, its model and projectN/AN/A4.0.0
Model deletedDeletedname of the model, name of the project spaceN/AN/A5.8.0
Workspace deletedDeletedthe name of the project space it belongs toN/AN/A5.8.0
Data source deletedDeletedthe name of the project space it belongs toN/AN/A5.8.0
Workflow deletedDeletedthe name of the project space it belongs toN/AN/A5.8.0
Submission deletedDeletedthe name of the project space it belongs toN/AN/A5.8.0
Dimension deletedDeletedthe name of the project space it belongs toN/AN/A5.8.0
Templates deletedDeletedthe name of the project space it belongs toN/AN/A5.8.0
Project variable deletedDeletedN/AN/AN/A5.8.0
Scenario variable deletedDeletedN/AN/AN/A5.8.0
A line item variant is deletedDeleteddata parameter variant’s keyN/AN/A5.8.0
Changing the project or application settingChanged settingA detailed description on which setting was changed, what was the previous value and what is the new valueN/AN/ASince beginning
Changing password of the userPassword changedN/AN/AN/ASince beginning
Changed data access permissions on a dimension or level (value)Data permissionsN/AN/AN/A3.1.0
Moving a nodeNode changed modelsold modelnew modelN/A4.0.0
A line item variant is updatedLine-item data changeN/AN/AN/A5.0.0
A line item was selected or unselected from a scenarioLine item selection’selected’ or ‘unselected’parameter’s keyN/A3.1.0
A line item variant is ‘selected’ or ‘unselected’ from being associated with a scenarioLine-item selection’selected’ or ‘unselected’data parameter variants’s keyN/A5.0.0
User enabled or disabledProperty change’enabled’old valuenew value3.7.0

Actions by users

EventAction typeAction Parameter 1Action Parameter 2Action Parameter 3Added in Version
User creates, deletes or reverts a versionVersioning action’versioned’, ‘shared’, ‘unshared’, ‘deleted version’ or ‘reverted’optional: the created version or version you are reverting fromoptional: workflow’s key if it was a submission3.1.0
User links or unlinks levelsObject linking’extended’ or ‘extension removed’the key of the level that we extending by or removing extension toN/A3.1.0
User removes a value from a levelProperty change’levelValueRemove’the valueN/A3.1.0
User changes a value of a levelProperty change’levelValueChange’the valueN/A3.1.0
User change a parent value of a valueProperty change’levelValueParentChange’the value<old_parent> → <new_parent>3.1.0
User renames an objectProperty change’name’old namenew name3.1.0
User changes a property on an objectProperty changename of the propertynew valueN/A3.1.0
User moves a line item from one group to anotherProperty change’movedFromGroup’ or ‘movedToGroup’the groupN/A3.1.0
User does an action on a debug pageSpecial admin actionaction nameHTTP method usedN/A3.1.0
User logged inUser logged in’preAuth’, ‘SAML’, ’ openIdConnect’ or no parameterN/AN/ASince beginning
User failed to loginFailed loginUser that failed to loginempty or ”credentials OK - user blocked’ or ‘credentials OK - IP blocked’N/ASince beginning
User uploads a file that may change a DS or dimension tableFile uploadN/AN/AN/A3.1.0
User downloaded log filesLog download’server.log’ or ‘securityAudit.csv’N/AN/A3.1.0
User was denied access to modify dataData permissions write deniedLevel valueData permission class nameN/A3.8.8
User performed an action that caused time dimension data to be regeneratedTime dimension change[<start_date>…<end_date>]…Q<year_start_quarter>N/AN/A3.1.0
User saved or discarded the workspaceWorkspace save action’save’, ‘discard’, ‘saveAs’N/AN/A3.1.0
User changed data of a line itemLine item data changeN/AN/AN/A3.1.0
User changed data of a line item variantLine item data changeN/AN/AN/A5.0.0
User changes line item nameProperty change‘name’old namenew name5.0.0
User changes line item slider minimumProperty change‘sliderMin’old valuenew value5.8.0
User changes line item slider maximumProperty change‘sliderMax’old valuenew value5.8.0
User changes line item slider stepProperty change‘sliderStep’old valuenew value5.8.0
User created new API keyAPI key createdN/AN/AN/A3.6.0
A user’s session ends either through an explicit logout or an inactivity timeout. NOTE: If the session ends to an inactivity logout it can take 30 - 40 minutes for it to be registered as having expired in the log. Thus the time of the log entry can not be seen as the time the session actually expired.User logged outUsername of the user associated with the sessionN/AN/A5.8.0
User changed the dimension table from a data source tableProperty change‘dimensionTable’‘autoDim’Audit key of the data source table5.8.0

Block events

EventAction typeAction Parameter 1Action Parameter 2Action Parameter 3Added in Version
User blocked, due to too many unsuccessful consecutive loginsUser blocked’unsuccessful logins’N/AN/ASince beginning
Blocked user manually unblockedUser unblocked’on boot’ or no parameterN/AN/ASince beginning
Blocking IPs due to too many unsuccessful consecutive logins from the same IPIP blockedThe blocked IPN/AN/ASince beginning

File export/import

EventAction typeAction Parameter 1Action Parameter 2Action Parameter 3Added in Version
Chart exportedFile export’Formatted export’ or ‘Raw export’N/AN/A5.8.0
Workspace ExportFile export’Formatted export’ or ‘Raw export’N/AN/A5.8.0
Line item Download ExcelFile Export’Data parameter download’DataParameter audit keyN/A5.8.0
Assumption group Download Excel (a separate log line is made for each line item in the assumption group)File Export’Assumption group download’AssumptionGroup audit keyN/A5.8.0
Download excel for all assumption groups (a separate log line is made for each line item in each of the assumption groups)File Export’Bulk workspace download’Workspace audit keyN/A5.8.0
Node data preview downloadFile ExportAudit key of either the Baseline or SimulationRun associated with the data previewN/AN/A5.8.0
Project exportFile ExportN/AN/AN/A5.8.0
Tampered project importTampered project importDetailed reason, one of: Missing signature; Signature does not match content; Invalid signatureN/AN/A6.0.0

Others

EventAction typeAction Parameter 1Action Parameter 2Action Parameter 3Added in Version
host header poisoning - The supplied host header is not included in the allowlistBad Host HeaderActual host headerN/AN/A3.3.0
Jdbc / Odata table importExternal Datasource importimported tables namesN/AN/A4.0.0
Was this page helpful?